Compliance

AICPA Flags Cookie-Cutter SOC 2 as Nonconforming

The AICPA Peer Review Board now treats identical SOC 2 reports across clients as failing professional standards. What that means if you are buying an audit.

AK
Ashok Kamat
Cybersecify
6 min read

The AICPA’s Peer Review Board issued a reviewer alert in May 2026 telling peer reviewers how to handle firms performing high-volume SOC 2 engagements on third-party compliance platforms. The specific failure it names is engagements that produce identical reports, risk assessments, sample sizes and testing procedures across different clients. In peer review terms those are nonconforming: not performed in accordance with professional standards in all material respects. From 1 June 2026, firms with SOC 2 practices are identified for structured monitoring. If you are buying a SOC 2 audit, this changes what you should ask before you sign.

Most coverage of SOC 2 is written for the company being audited. This one is about the auditors, which is why it matters to you: it tells you what their own regulator has decided is not good enough.

Everything below is quoted from the Journal of Accountancy’s report, which is the AICPA’s own publication.

What the AICPA actually said

Carl Mayes, CPA, the AICPA’s vice president for Ethics and Firm Quality:

Some firms are leaning too heavily on third-party SOC platforms without applying the professional judgment required by our standards. Regardless of the tools used, CPAs must remain competent, objective, independent, and committed to engagements that reflect the unique risks and circumstances of each client.

And the failure pattern, stated precisely:

One specific risk is that a firm’s SOC 2 engagements are not designed to respond to the unique risks associated with the service organization, resulting in engagements that have identical reports, risk assessments, sample sizes, and testing procedures. In such circumstances, these engagements are not performed in accordance with the relevant professional standards in all material respects. In peer review, this is known as a “nonconforming” engagement.

Read that second quote slowly. The problem is not that a firm used software. The problem is that the output was the same for every client, which is evidence the engagement was never designed for any of them.

What “nonconforming” costs the firm

A nonconforming conclusion is not a note in a file. It increases the likelihood that the firm carries a deficiency or significant deficiency in its peer review report, and that it has to complete a follow-up action: revising its system of quality management, or having an outside party review completed engagements.

That is a real consequence for the firm, and it is the reason this alert has teeth rather than being guidance nobody acts on.

The five-report test

The part worth knowing as a buyer is how reviewers are now told to look. Where elevated risk is identified, the response may include:

  • Selecting several SOC 2 engagements, often about five, from different partners
  • Comparing those reports to one another and to prior-year reports
  • Reviewing targeted areas that require engagement-specific judgment
  • Determining whether identical risk assessments, control designs, sample sizes, or testing procedures appear across engagements

Reviewers are also guided to understand the firm’s use of technology including external SOC platforms, the reasonableness of engagement timelines, and whether engagements are tailored to each client’s environment.

The timelines line is the one that should make a buyer pause. A quoted turnaround that seems impressively short is now something the auditor’s own regulator treats as a risk indicator.

What this does not mean

Three clarifications, because this is being misread already.

It is not a finding against compliance platforms. The alert addresses how some firms use them. A platform can be part of a well-run engagement. What fails is a firm substituting the tool for its own judgement. If you are running Vanta, Drata or a comparable platform, nothing here says you chose wrong.

It does not make your existing report invalid. Peer review examines the firm’s practice. It is not a recall of issued reports.

It does not apply to penetration testing vendors. AICPA peer review governs CPA firms performing the SOC 2 examination. We are not a CPA firm, we do not perform or sign the examination, and we refer that work to a CPA partner. Anyone in our line of business presenting this alert as vindication of themselves is doing the thing the alert is about.

Four questions to ask your auditor

All four are answerable in writing, and a firm running a tailored engagement will not find them difficult.

  1. When was your last peer review, and what was the result? Peer review results are a matter of record. A firm that will not discuss it is telling you something.
  2. How does the risk assessment for our engagement differ from the last client you did in our industry? You are not asking for their client’s details. You are asking whether a risk assessment happened.
  3. What determined our sample sizes? “The platform’s default” is an answer, and it is the one the alert is about.
  4. Which parts of this engagement run on a platform, and which involve your own testing? A good firm answers this happily, because the split is the value they add.

The principle, which travels further than the jurisdiction

Strip away who it governs and the alert says something simple: a deliverable that is identical across different clients was not designed for any of them.

That is worth holding onto beyond SOC 2, because it is the same test a buyer should apply to a penetration test report. If two companies with different architectures, different user roles and different data receive reports with the same findings in the same order, the report describes the tool that produced it rather than the system it was pointed at. That is why we publish our sample report in full, with the reproduction steps and the client-specific business impact visible, rather than describing it.

The AICPA has now written that principle down for auditors. It was always true of assurance work generally.

Where we fit, stated plainly

We produce the penetration test and the report that goes into your SOC 2 evidence package, with each finding mapped to the Trust Services Criteria. We do not perform the examination, we do not issue the opinion, and the CPA partner does that work. If you want the detail of how the mapping works, our audit and compliance readiness page covers it, and our SOC 2 Trust Services Criteria explainer covers the criteria themselves.

The reason to read this alert is not to pick a pentest vendor. It is to ask better questions of whoever signs your report.

Sources

Frequently Asked Questions

What is a nonconforming SOC 2 engagement?

In AICPA peer review terms, a nonconforming engagement is one not performed in accordance with the relevant professional standards in all material respects. The May 2026 reviewer alert names a specific pattern: a firm's SOC 2 engagements that are not designed to respond to the unique risks of the service organisation, producing identical reports, risk assessments, sample sizes and testing procedures across different clients. A nonconforming conclusion increases the likelihood that the firm has a deficiency or significant deficiency in its peer review report, and that it has to complete a follow-up action such as revising its system of quality management or having completed engagements reviewed by an outside party.

Does this mean compliance platforms like Vanta or Drata are non-compliant?

No, and reading it that way misstates the alert. The AICPA is addressing how some CPA firms use third-party SOC platforms, not the platforms themselves. Carl Mayes, the AICPA's VP of Ethics and Firm Quality, put it as firms leaning too heavily on third-party SOC platforms without applying the professional judgment required by the standards, and added that regardless of the tools used, CPAs must remain competent, objective and independent. A platform can be part of a well-run engagement. The failure being described is a firm substituting the tool for its own judgement.

How do peer reviewers now check for this?

Where a reviewer concludes that elevated risk exists, the alert says the response may include selecting several SOC 2 engagements, often about five, from different partners, then comparing those reports to one another and to prior-year reports, and determining whether identical risk assessments, control designs, sample sizes or testing procedures appear across engagements. Reviewers are also guided to obtain a deeper understanding of the firm's use of technology including external SOC platforms, the reasonableness of engagement timelines, and whether engagements are tailored to each client's environment.

What should I ask my SOC 2 auditor because of this?

Four questions, all answerable in writing. Ask when the firm's last peer review was and what the result was. Ask how the risk assessment for your engagement differs from the previous client in your industry. Ask what determined your sample sizes. And ask which parts of the engagement are performed on a platform and which involve the auditor's own testing. A firm running a tailored engagement can answer all four without difficulty. A firm that cannot is describing the pattern the alert was written about.

Does this apply to penetration testing vendors?

No. AICPA peer review governs CPA firms performing the SOC 2 examination. It does not govern penetration testing vendors, and Cybersecify is not a CPA firm and does not perform or sign the SOC 2 examination. The reason it is worth reading anyway is the principle rather than the jurisdiction: an auditor's own standards body has written down that identical deliverables across different clients indicate work that was not designed for the client. That is a reasonable test to apply to any assurance deliverable you buy, including a pentest report.

Security questions, worries, or not sure what to use?

Cybersecify is a founder-led penetration testing firm for AI and SaaS startups. Tell us what you are weighing and we will give you a straight answer. Ask the team or book a free 30-minute call.

Share this article
SOC 2AICPAComplianceAudit

Spotted something wrong on this page? Facts change and we get things wrong. Tell us and we will check it. We publish corrections on the page rather than editing quietly.